Obsahuje:
  • všechny e-ziny od 9/1999
  • celou databázi NEWS
  • soutěže 2000-2011
  • další články a BONUSY

Security - News

http://crypto-world.info

Crypto - News | Security - News

02 / 2007
Vybrali pro vás: TR - Tomáš Rosa, JP - Jaroslav Pinkava, PV - Pavel Vondruška, VK - Vlastimil Klíma

Útok SQL injection - soubor odkaz?

06.02.2007
Série odkaz? - informace a doporu?ení.

Z definice:

SQL injection is a type of security exploit in which the attacker adds Structured Query Language (SQL) code to a Web form input box to gain access to resources or make changes to data. An SQL query is a request for some action to be performed on a database. Typically, on a Web form for user authentication, when a user enters their name and password into the text boxes provided for them, those values are inserted into a SELECT query. If the values entered are found as expected, the user is allowed access; if they aren't found, access is denied. However, most Web forms have no mechanisms in place to block input other than names and passwords. Unless such precautions are taken, an attacker can use the input boxes to send their own request to the database, which could allow them to download the entire database or interact with it in other illicit ways.
Zdroj: http://searchappsecurity.techtarget.com/featuredTopic/0,290042,sid92_gci1164790,00.html?track=NL-516&ad=578350&asrc=EM_USC_967259&uid=4690023
Autor: JP


<<- novější - K firewallu ve Windows Vista
Práv? probíhá - RSA Conference 2007 - starší ->>
Design: Webdesign